CVE-2026-48142

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-48142 is a vulnerability affecting NGINX Plus and NGINX Open Source, specifically within the `ngx_http_charset_module`. This flaw arises when a location block is configured with both `source_charset utf-8;` and an additional `charset` directive, such as `charset koi8-r;`. Under these specific conditions, remote and unauthenticated attackers can send specially crafted requests. These requests can exploit the vulnerability to cause a heap buffer over-read in the NGINX worker process, which may result in limited disclosure of memory or a process restart.

Description
-

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.